This thread's last reply is from September 14, 2007, 10:49 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
I need some help. I am running McAfee Security Center and it fails to detect this.
Three days ago my Internet Explorer started freezing up whenever I opened it.
Luckily, I already had Firefox on my computer and have been able to access the internet using it.
I found entries in IE history for "a.whataboutarabit" and "b.whataboutadog", both of which I have since found out are related to the trojan Zonebac.
I ran a Hijackthis scan, the results of which are pasted below.
Any help would be greatly appreciated.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:06:29 PM, on 8/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark 3300 Series\lxccmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Home Publishing\MHPRMIND.EXE
C:\Program Files\Lexmark 3300 Series\bak\lxccmon.exe
C:\WINDOWS\System32\lxcccoms.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
file://C:/WINDOWS/system32/drivers/etc/proxy
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
R3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {07A0995F-51C3-5C61-947B-0D157718E09D} - C:\WINDOWS\System32\arnfkes.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: XBTB04482 - {A9BE1152-9DB7-4e4f-8F33-B314A5E364D7} - C:\WINDOWS\DOWNLO~1\toolbar.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {F3001A40-8185-D475-D749-8B1D874317C7} - C:\WINDOWS\System32\pibipbpx.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [lxccmon.exe] "C:\Program Files\Lexmark 3300 Series\lxccmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-809299238-3928787509-1647371527-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - Startup: Microsoft Greetings Reminders.lnk = C:\Program Files\Microsoft Home Publishing\MHPRMIND.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &AOL Toolbar search -
res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Display All Images with Full Quality -
res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality -
res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.whataboutadog.com
O15 - Trusted Zone: *.whataboutarabit.com
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) -
http://forms.real.com/real/player/downl ... st_Win.cab
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex/DIGHardwareControl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/06869d73e24033c22119/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128223043475
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128222990209
O16 - DPF: {776706AE-CACA-4EA3-93DF-BB83D9259DA9} (MailConfigure Class) - http://supportservices.msn.com/us/oeconfig/MailCfg.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.25/ttinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://playgames.comcast.net/online2/chuzzle/popcaploader_v6.cab
O23 - Service: McAfee Application Installer Cleanup (0239721187844852) (0239721187844852mcinstcleanup) - McAfee, Inc. - C:\DOCUME~1\WILLIA~1\LOCALS~1\Temp\023972~1.EXE
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxcccoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
--
End of file - 12661 bytes
askey127,
Thank you so much for your help. I was beginning to think that no one was going to reply to my post.
I followed all of the directions from your first post.
Here is the info that you requested.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:23:46 PM, on 8/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Lexmark Fax Solutions\fm3032.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\TrojanHunter 4.7\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Home Publishing\MHPRMIND.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
file://C:/WINDOWS/system32/drivers/etc/proxy
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxccmon.exe] "C:\Program Files\Lexmark 3300 Series\lxccmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.7\THGuard.exe"
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Microsoft Greetings Reminders.lnk = C:\Program Files\Microsoft Home Publishing\MHPRMIND.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &AOL Toolbar search -
res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Display All Images with Full Quality -
res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality -
res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) -
http://forms.real.com/real/player/downl ... st_Win.cab
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex/DIGHardwareControl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128223043475
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1128222990209
O16 - DPF: {776706AE-CACA-4EA3-93DF-BB83D9259DA9} (MailConfigure Class) - http://supportservices.msn.com/us/oeconfig/MailCfg.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.15.25/ttinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.5/installer.exe
O23 - Service: McAfee Application Installer Cleanup (0239721187844852) (0239721187844852mcinstcleanup) - Unknown owner - C:\DOCUME~1\WILLIA~1\LOCALS~1\Temp\023972~1.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxcccoms.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
--
End of file - 11146 bytes
CCleaner text file:
3D Groove Playback Engine
56Kbps Internal Modem
ABBYY FineReader 6.0 Sprint Plus
Adobe Acrobat 5.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Shockwave Player
ALLTELrace Screen Saver
Amazing Animals
Ariel's Story Studio
Arthur's Birthday
Arthur's Computer Adventure
aspi
ATI Control Panel
ATI Display Driver
ATI DVD Decoder
ATI Multimedia Center 7.8.0.0
Avance AC'97 Audio
BigFix
BVHE-Beauty and the Beast Magical Ballroom
C-Media WDM Audio Driver
CCHelp
CCleaner (remove only)
CCScore
CDBurnerXP Pro 3
Chutes and Ladders
Comcast PhotoShow Deluxe 4
Comcast Toolbar
CompuServe
CR2
DAO
DeductionPro 2003
Delta EPF Installer
DeltaNet VPN Connector
Disney's Active Play LKII, Simba's Pride Demo
Disney's Active Play, A Bug's Life
Disney's Princess Fashion Boutique
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSTUTOR
ESSvpaht
ESSvpot
Finding Nemo: Nemo's Underwater World of Fun Special Edition
Google Earth
Google Toolbar for Internet Explorer
GUIDE PLUS+(TM) for Windows® System - ATI
HijackThis 2.0.2
HLPCCTR
HLPIndex
HLPPDOCK
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB926239)
HydraVision
ICQ
Java 2 Runtime Environment Standard Edition v1.3.1_02
Java 2 Runtime Environment, SE v1.4.2_03
JD Secure 3.1
Jimmy Neutron vs. Jimmy Negatron DEMO
Jumpstart 2nd Grade Math v1.1
JumpStart 2nd Grade v1.1
JumpStart 3rd Grade v1.1
JumpStart Baby v1.0
Jumpstart First Grade v1.4
JumpStart Kindergarten 98 v2.3
JumpStart Kindergarten Reading v1.0
JumpStart Music
JumpStart PreSchool v1.4
JumpStart Spy Masters Training
JumpStart Typing v1.0
Kodak EasyShare software
KSU
Lexmark 3300 Series
Lexmark Fax Solutions
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Logitech Desktop Messenger
Logitech iTouch Software
Logitech MouseWare 9.79.3
McAfee SecurityCenter
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Greetings
Microsoft Money 2003 System Pack
Microsoft Money 2003
Microsoft Picture It! Express 2000
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works 7.0
Minigolf Space
Mozilla Firefox (2.0.0.6)
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
NASCAR Thunder TM 2003
Netscape 6 (6.2.1)
NetZero Connection Wizard
NetZero HiSpeed (remove only)
NetZero
Notifier
OTtBP
PCDLNCH
Pinball Panic
PowerDVD
Princess Magical Dress-Up
ProSavageDDR and Utilities
QuickTime for Windows (32-bit)
QuickTime
RealPlayer
Rhapsody Player Engine
Ryan Newman Fan Club
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
SFR2
SFR
SpongeBob SquarePants - Battle for Bikini Bottom DEMO
SpongeBob SquarePants Diner Dash (remove only)
Super SpongeBob Collapse!
Tarzan's Jungle Tumble
TaxCut 2001
TaxCut 2002
TaxCut 2003
The Fairly OddParents Demo
Thomas & Friends - Railway Adventures
TrojanHunter 4.7
Unreal
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB938828)
USA Explorer
USB Multimedia Keyboard Driver Ver1.5a
Valu-Soft Product
VCAMCEN
Viewpoint Manager (Remove Only)
Viewpoint Media Player (Remove Only)
VPRINTOL
WebFldrs XP
Winamp (remove only)
Windows Backup Utility
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
http://www.find.fm Toolbar
In addition to that, I had the following error box on reboot.
fm3032.exe - Unable To Locate Component
This application has failed to start because fm3032.dll was not found. Re-installing the application may fix this problem.
My internet service is provided by Comcast.
Thanks Again,
Bill
asket127,
Here is the contents from starter:
Process,PID,"Mem usage",Executable,Priority,"Page fault count","Mem usage (peak)","Paged pool (peak)","Paged pool","Nonpaged pool (peak)","Nonpaged pool","Pagefile (peak)",Pagefile
Idle,0,,,,,,,,,,,
System,4,"241,664",,"20 (Normal)","6,193","2,859,008",,,,,,
ScsiAccess.EXE,148,"942,080",C:\WINDOWS\System32\ScsiAccess.EXE,"20 (Normal)*",226,"942,080","9,416","9,416","1,632","1,072","311,296","311,296"
svchost.exe,152,"4,489,216",C:\WINDOWS\System32\svchost.exe,"20 (Normal)","1,150","4,489,216","38,984","38,408","8,574","6,096","1,839,104","1,839,104"
MHPRMIND.EXE,216,"1,581,056","C:\Program Files\Microsoft Home Publishing\MHPRMIND.EXE","20 (Normal)",424,"1,581,056","17,340","16,168","2,456","1,480","389,120","385,024"
slserv.exe,320,"925,696",C:\WINDOWS\system32\slserv.exe,"20 (Normal)*",222,"925,696","9,132","9,132","1,704","1,080","286,720","286,720"
svchost.exe,356,"6,332,416",C:\WINDOWS\System32\svchost.exe,"20 (Normal)*","1,673","6,385,664","38,880","38,524","5,480","4,480","4,046,848","3,981,312"
spoolsv.exe,612,"6,668,288",C:\WINDOWS\system32\spoolsv.exe,"20 (Normal)*","3,786","7,118,848","45,216","43,328","9,472","5,592","4,825,088","4,603,904"
KodakCCS.exe,784,"2,969,600",C:\WINDOWS\system32\drivers\KodakCCS.exe,"20 (Normal)*",917,"3,227,648","35,240","30,664","7,760","7,760","1,060,864","970,752"
smss.exe,824,"380,928",C:\WINDOWS\System32\smss.exe,"20 (Normal)*",211,"475,136","13,328","5,248","1,240",640,"1,712,128","167,936"
HWAPI.exe,852,"3,391,488","C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe","20 (Normal)*","5,577","11,608,064","46,452","38,760","11,312","7,752","9,175,040","9,113,600"
mcmscsvc.exe,880,"4,571,136",C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe,"20 (Normal)*","8,360","4,964,352","44,136","42,608","8,480","6,880","3,620,864","3,293,184"
mcnasvc.exe,992,"9,932,800","c:\program files\common files\mcafee\mna\mcnasvc.exe","20 (Normal)*","11,561","12,054,528","59,600","55,536","43,848","40,432","5,328,896","4,861,952"
mcpromgr.exe,1080,"921,600",C:\PROGRA~1\McAfee\MSC\mcpromgr.exe,"20 (Normal)*","51,938","14,688,256","60,000","58,944","14,160","12,520","8,785,920","8,265,728"
mcods.exe,1092,"630,784",C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe,"20 (Normal)*","2,831","5,054,464","42,500","37,488","7,288","5,888","2,699,264","2,674,688"
csrss.exe,1160,"3,751,936",C:\WINDOWS\system32\csrss.exe,"20 (Normal)*","3,792","4,206,592","63,600","63,264","6,800","6,168","3,608,576","1,466,368"
winlogon.exe,1228,"4,136,960",C:\WINDOWS\system32\winlogon.exe,"80 (High)*","6,955","15,925,248","64,840","59,112","50,832","48,032","9,904,128","6,721,536"
mcproxy.exe,1240,"6,438,912",c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe,"20 (Normal)*","2,022","6,619,136","42,736","38,152","25,016","21,672","5,210,112","5,009,408"
redirsvc.exe,1280,"4,599,808",c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe,"20 (Normal)*","1,426","4,616,192","35,312","28,036","7,184","5,648","2,428,928","2,416,640"
services.exe,1304,"3,481,600",C:\WINDOWS\system32\services.exe,"20 (Normal)*","3,189","3,551,232","28,100","26,892","9,096","8,096","1,966,080","1,871,872"
lsass.exe,1316,"1,429,504",C:\WINDOWS\system32\lsass.exe,"20 (Normal)*","2,011","5,943,296","42,012","37,652","9,240","6,272","2,600,960","2,494,464"
mcshield.exe,1468,"22,413,312",C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe,"80 (High)*","70,777","55,164,928","48,504","47,404","14,600","11,528","52,097,024","30,756,864"
Ati2evxx.exe,1540,"2,211,840",C:\WINDOWS\system32\Ati2evxx.exe,"20 (Normal)*",573,"2,211,840","21,224","19,496","2,344","1,896","561,152","561,152"
svchost.exe,1552,"5,267,456",C:\WINDOWS\system32\svchost.exe,"20 (Normal)*","1,460","5,312,512","41,968","40,228","7,880","6,664","23,973,888","3,346,432"
mcsysmon.exe,1620,"6,950,912",C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe,"20 (Normal)*","10,350","7,995,392","49,072","42,968","9,648","8,688","4,345,856","4,218,880"
svchost.exe,1648,"4,427,776",C:\WINDOWS\system32\svchost.exe,"20 (Normal)","1,222","4,431,872","38,816","38,116","16,096","13,928","2,011,136","2,007,040"
mpsevh.exe,1720,"839,680","C:\Program Files\McAfee\MPS\mpsevh.exe","20 (Normal)","3,579","5,455,872","47,392","47,240","8,320","7,200","3,227,648","3,203,072"
MPFSrv.exe,1808,"5,357,568","C:\Program Files\McAfee\MPF\MPFSrv.exe","20 (Normal)*","15,330","11,964,416","48,436","48,156","12,584","8,792","8,269,824","5,275,648"
svchost.exe,1904,"20,504,576",C:\WINDOWS\System32\svchost.exe,"20 (Normal)*","11,906","27,328,512","126,408","119,152","64,512","61,120","22,806,528","13,029,376"
mps.exe,1928,"2,285,568",C:\PROGRA~1\McAfee\MPS\mps.exe,"20 (Normal)*","18,814","7,507,968","46,492","44,604","8,584","7,344","7,102,464","6,291,456"
mcvsshld.exe,2120,"8,933,376",c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe,"20 (Normal)","2,936","8,941,568","48,792","48,088","10,040","7,920","3,887,104","3,850,240"
mcagent.exe,2268,"1,294,336",c:\PROGRA~1\mcafee.com\agent\mcagent.exe,"20 (Normal)","5,065","8,818,688","47,584","46,472","8,880","7,600","3,923,968","3,846,144"
alg.exe,2472,"3,571,712",C:\WINDOWS\System32\alg.exe,"20 (Normal)",904,"3,579,904","36,284","35,884","5,888","5,168","1,183,744","1,171,456"
lxccmon.exe,2736,"4,313,088","C:\Program Files\Lexmark 3300 Series\lxccmon.exe","20 (Normal)","1,326","4,374,528","40,696","36,112","4,256","3,240","1,310,720","1,298,432"
SOUNDMAN.EXE,2816,"2,478,080",C:\WINDOWS\SOUNDMAN.EXE,"20 (Normal)",637,"2,478,080","33,628","28,728","2,200","1,920","1,789,952","1,789,952"
mHotkey.exe,2824,"4,096,000",C:\WINDOWS\mHotkey.exe,"20 (Normal)","1,107","4,096,000","37,060","33,744","3,848","2,640","2,400,256","2,375,680"
Logi_MwX.Exe,2856,"2,060,288",C:\WINDOWS\Logi_MwX.Exe,"20 (Normal)",559,"2,154,496","32,636","26,440","2,200","1,680","581,632","565,248"
THGuard.exe,2972,"8,486,912","C:\Program Files\TrojanHunter 4.7\THGuard.exe","20 (Normal)","144,655","9,752,576","36,800","31,544","3,000","2,320","6,975,488","5,459,968"
jusched.exe,3116,"2,310,144","C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe","20 (Normal)",612,"2,310,144","36,960","29,720","2,400","1,920","712,704","671,744"
lxccmon.exe,3128,"4,042,752","C:\Program Files\Lexmark 3300 Series\bak\lxccmon.exe","20 (Normal)","1,844","4,059,136","37,420","36,364","4,200","3,640","1,134,592","1,032,192"
msmsgs.exe,3148,"5,607,424","C:\Program Files\Messenger\msmsgs.exe","20 (Normal)","2,839","5,615,616","50,368","48,688","12,456","10,456","3,502,080","3,489,792"
GoogleToolbarNotifier.exe,3184,"1,212,416","C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe","20 (Normal)",363,"1,257,472","16,384","16,012","1,864","1,240","458,752","393,216"
Starter.exe,3192,"7,958,528",C:\Downloads\Simtel\start562\Starter.exe,"20 (Normal)","3,557","7,974,912","47,256","38,636","5,800","5,080","5,591,040","5,390,336"
IEXPLORE.EXE,3396,"19,873,792","C:\Program Files\Internet Explorer\IEXPLORE.EXE","20 (Normal)","6,333","20,656,128","85,560","68,756","17,024","13,360","11,534,336","11,022,336"
Ati2evxx.exe,3456,"2,887,680",C:\WINDOWS\system32\Ati2evxx.exe,"20 (Normal)",920,"3,604,480","27,304","22,868","4,448","2,168","2,007,040","729,088"
firefox.exe,3592,"28,495,872","C:\Program Files\Mozilla Firefox\firefox.exe","20 (Normal)","17,603","36,929,536","70,400","55,912","17,904","12,360","28,233,728","19,562,496"
Explorer.EXE,3632,"19,308,544",C:\WINDOWS\Explorer.EXE,"20 (Normal)","16,444","20,434,944","68,468","58,508","15,904","14,448","16,105,472","13,451,264"
lxcccoms.exe,3700,"4,640,768",C:\WINDOWS\System32\lxcccoms.exe,"80 (High)*","1,272","4,648,960","29,784","29,648","4,672","3,696","2,265,088","2,252,800"
wmiprvse.exe,3780,"4,784,128",C:\WINDOWS\System32\wbem\wmiprvse.exe,"20 (Normal)*","1,244","4,894,720","37,556","37,012","5,568","3,960","3,047,424","2,785,280"
iexplore.exe,4000,"18,468,864","c:\program files\internet explorer\iexplore.exe","20 (Normal)","5,735","18,726,912","73,560","64,444","14,440","12,968","10,739,712","10,620,928"